First published: Wed Sep 27 2023(Updated: )
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpkobo AjaxNewsTicker | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41445 is a Cross Site Scripting (XSS) vulnerability in phpkobo AjaxNewTicker v.1.0.5.
CVE-2023-41445 allows a remote attacker to execute arbitrary code by sending a crafted payload to the index.php component.
The severity of CVE-2023-41445 is medium, with a CVSS score of 6.1.
Version 1.0.5 of phpkobo AjaxNewTicker is affected by CVE-2023-41445.
To fix CVE-2023-41445, update to a version of phpkobo AjaxNewTicker that is not affected by the vulnerability.